PT-2019-16668 · Dell Emc · Dell Openmanage Server Administrator

Published

2019-06-06

·

Updated

2019-10-09

·

CVE-2019-3723

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.2.0.4
Description The issue allows a remote unauthenticated attacker to manipulate parameters of web requests to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation.
Recommendations For versions prior to 9.1.0.3, update to version 9.1.0.3 or later. For versions prior to 9.2.0.4, update to version 9.2.0.4 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3723

Affected Products

Dell Openmanage Server Administrator